The Hacker News
- Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report [30m]
- Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools [3h]
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes [6h]
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers [19h]
- ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories [19h]
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory [21h]
- How Financial Services Companies Can Modernize Their Software Supply Chain [1d]
- OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates [1d]
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV [1d]
- Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version [1d]
BleepingComputer
- Microsoft’s X account hacked in crypto pump-and-dump scheme [2h]
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks [13h]
- Autonomous AI agents tried to hack US, Canadian government websites [15h]
- Microsoft says threat actors are ahead in the early AI race [16h]
- Police dismantle KillSec ransomware gang allegedly led by 16-year-old [21h]
- The Day-One Hole in Zero Trust Architecture [21h]
- Kiteworks patches max severity code injection vulnerability [22h]
- Microsoft enables Windows settings backup by default for orgs [1d]
- Hackers stole Pentagon personnel records of over 3 million people [1d]
- Metamask discloses security incident affecting its infrastructure [1d]
- Russian state hackers use new RedFlick technique to push malware [1d]
- DIVD says Zammad zero-days enabled AI-driven network breach [1d]
- Over 543,000 valid credentials exposed in public GitHub repositories [1d]
- CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS [1d]
- Cisco warns of new SD-WAN zero-day exploited in attacks [1d]
- AI's Third Wave: Coworkers Break the Security Model That Worked for Agents [1d]
- Microsoft to block Entra ID script injection attacks starting October [1d]
- TeamViewer urges users to patch severe flaws “as soon as possible” [1d]
- Bitget hacked via zero-day in third-party security products [2d]
- Microsoft is rolling out Linux container support to WSL [2d]
- Signal adds encypted local backup support to iOS, desktop apps [2d]
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware [2d]
- FBI tells ShinyHunters members to turn themselves in after recent arrest [2d]
- Hackers exploit Citrix NetScaler zero-day to deploy web shells [2d]
- Former US Air Force members sent to prison over BEC attacks [2d]
Dark Reading
- [Virtual Event] Cybersecurity Outlook 2027 [now]
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI [now]
- [Virtual Event] Building a Secure AI Strategy for the Enterprise [now]
- Alleged KillSec Ransomware Mastermind a 16-Year-Old [14h]
- Warlock Ransomware Hits Large Spanish, Portuguese Orgs [23h]
- Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure [1d]
- Trump, Tech Giants Strike Voluntary AI Safety Accord [1d]
- As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half [1d]
- Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net [1d]
- South Africa Seeks Help After Cyberattack Targets Air Traffic Control [2d]
- Apple Zero-Day Vulnerability Weaponized in Targeted Attacks [2d]
- Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution [2d]
- Cloudflare Announces Public Certificate Authority for the Post-Quantum Web [2d]
- 'NeedyMantis' Provides Long-Term Access to Compromised Networks [2d]
- Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers [2d]
The Record
- Iranian accused of hacking American universities extradited from Montenegro [15h]
- OpenAI software attempted to secretly scrape data from dozens of prominent websites [16h]
- Researchers find Chinese hacking campaigns targeting AI firms, Asian governments [17h]
- Police disrupt KillSec ransomware, arrest suspected teenage leader [20h]
- Cyberattack on major Polish invoicing platform exposes customer data [23h]
- US sanctions 10 over ATM malware scheme tied to Tren de Aragua [1d]
- Automakers routinely share personally identifiable connected-car data with third parties, report says [1d]
- After reports on suicide deaths, Pentagon puts Cyber Command on notice [1d]
- Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation [1d]
- Mobile malware warning from Ukrainian researchers includes iPhone exploit kit [1d]
- Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters [2d]
- US Air Force members given over 6 years in prison for cyber theft of more than $2 million [2d]
- Controversial spyware firm Paragon to go public by end of year [2d]
- OpenAI apologizes for agents breaching Australian government websites without authorization [2d]
- Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims [2d]
- Arizona Supreme Court says hackers stole residents’ personal data [2d]
CyberScoop
- Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members [16h]
- National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations [16h]
- AI policy circles targeted in China-linked phishing operation [21h]
- OpenAI reveals ‘novel’ encryption bypass used in distillation attack [1d]
- WaterISAC reckons with range of threats after summer of cyberattacks [2d]
- Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected [2d]
- Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond [2d]
- US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says [2d]
- Alleged ShinyHunters leader arrested in the Netherlands [2d]
- Kiteworks lifts shutdown advisory after ‘credible threat intelligence’ from federal authorities [2d]
SANS ISC
- ISC Stormcast For Friday, October 2nd, 2026 https://isc.sans.edu/podcastdetail/10120 [10h]
- ScreenConnect Client (Ab)used by Attackers [1d]
- ISC Stormcast For Thursday, October 1st, 2026 https://isc.sans.edu/podcastdetail/10118 [1d]
- ISC Stormcast For Wednesday, September 30th, 2026 https://isc.sans.edu/podcastdetail/10116 [2d]
- Scans for Wordfence Protected Websites [2d]
Schneier on Security
Rapid7 Blog
Malwarebytes Labs
- Fake xStocks, Pendle, and other sites bait crypto users with rewards votes [18h]
- Shadow AI explained: The work shortcut that could leak your company’s secrets [21h]
- Malwarebytes earns another Top Product award in independent testing [1d]
- Pentagon breach exposes Social Security numbers and military records of millions [1d]
- Losing gamblers pushed to bet more by DraftKings’ AI, report says [1d]
- Hackers steal protective order and foster care records from Arizona courts [1d]
- Your car’s app could be telling Big Tech who you are and where you go [2d]
- Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home [2d]
Graham Cluley
WeLiveSecurity (ESET)
Unit 42 (Palo Alto)
CISA Advisories
- Armatura LLC Armatura One [1d]
- Monta monta.app [1d]
- Johnson Controls EasyIO Neo Series EC and CW Controllers [1d]
- Meari IoT Cloud Platform OpenAPI Service [1d]
- ABB Protection and Control IED Manager PCM600 [1d]
- Johnson Controls EasyIO Neo Series EC and CW Controllers [1d]
- CISA Malcolm [1d]
- CISA Adds One Known Exploited Vulnerability to Catalog [1d]
- CISA Adds One Known Exploited Vulnerability to Catalog [2d]
Zero Day Initiative
- ZDI-26-751: Microsoft Windows dxgkrnl Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability [1d]
- ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability [2d]
- ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability [2d]